A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-32910

CVE-2025-32910: libsoup DOS Vulnerability

CVE-2025-32910 is a denial of service flaw in libsoup that triggers a NULL pointer dereference in soup_auth_digest_authenticate(), causing client crashes. This article covers technical details, affected versions, and mitigation.

Updated: May 14, 2026

CVE-2025-32910 Overview

CVE-2025-32910 is a NULL pointer dereference vulnerability in libsoup, an HTTP client/server library widely used by GNOME applications and other Linux software. The flaw resides in the soup_auth_digest_authenticate() function, which handles HTTP Digest authentication. A malicious server can send a crafted response that triggers the dereference, causing the libsoup-based client to crash. The vulnerability is classified as [CWE-476] and affects availability without impacting confidentiality or integrity. Network-based exploitation requires user interaction, such as connecting to or fetching a resource from an attacker-controlled endpoint.

Critical Impact

A remote attacker controlling an HTTP server can crash any libsoup client that authenticates against it, causing denial of service for applications relying on the library.

Affected Products

  • libsoup HTTP library (upstream)
  • Red Hat Enterprise Linux distributions referencing RHSA-2025:8292
  • Debian LTS releases shipping vulnerable libsoup packages

Discovery Timeline

  • 2025-04-14 - CVE-2025-32910 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2025-32910

Vulnerability Analysis

The defect lives in soup_auth_digest_authenticate(), the routine libsoup uses to compute and apply HTTP Digest authentication credentials. When the function processes authentication state, it dereferences a pointer without first verifying that the underlying field is non-NULL. The result is a process crash inside the client application.

This is a classic [CWE-476] NULL pointer dereference. Because libsoup is embedded in many desktop and server applications, including GNOME components, browsers, and update tools, the crash propagates to whichever process loaded the library. The vulnerability impacts availability only; it does not enable code execution or data disclosure.

Exploitation requires user interaction. A user must initiate a request to a malicious or compromised server, after which the server returns crafted authentication headers that trigger the dereference during client-side processing.

Root Cause

The root cause is missing input validation inside soup_auth_digest_authenticate(). The function assumes that required Digest authentication parameters were successfully parsed and populated, but it does not check for NULL before accessing them. When a malformed or unexpected authentication challenge omits an expected field, the resulting pointer is NULL and the dereference faults.

Attack Vector

The attack vector is network-based with low complexity and no privileges required. An attacker hosts a malicious HTTP server, or tampers with traffic in a position to alter authentication responses, and entices a libsoup-based client to authenticate. When the client invokes Digest authentication, the crafted server response forces a NULL dereference and the client process terminates. See the Red Hat CVE-2025-32910 advisory and the Red Hat Bug Report #2359354 for upstream technical details.

Detection Methods for CVE-2025-32910

Indicators of Compromise

  • Repeated unexpected crashes of applications linked against libsoup (for example, GNOME Online Accounts, Evolution, gnome-software, or other HTTP clients) shortly after issuing outbound HTTP requests.
  • Core dumps or systemd-coredump entries referencing soup_auth_digest_authenticate in the call stack.
  • Outbound HTTP connections to untrusted hosts returning Digest authentication challenges with missing or malformed parameters.

Detection Strategies

  • Monitor application crash telemetry and journald logs for segmentation faults in processes that load libsoup-2.4.so or libsoup-3.0.so.
  • Inspect network traffic for HTTP 401 Unauthorized responses containing malformed WWW-Authenticate: Digest headers directed at internal hosts.
  • Correlate crash events with preceding outbound HTTP sessions to identify the triggering server.

Monitoring Recommendations

  • Forward systemd-coredump and abrt events to a central logging or SIEM platform for review.
  • Track installed libsoup package versions across the fleet and alert on hosts running pre-patch builds.
  • Baseline normal HTTP authentication patterns and alert on unusual Digest challenges from previously unseen domains.

How to Mitigate CVE-2025-32910

Immediate Actions Required

  • Apply the libsoup updates referenced in Red Hat Security Errata RHSA-2025:8292 and the Debian LTS Security Announcement.
  • Restart services and desktop sessions after upgrade so updated library code is loaded by long-running processes.
  • Inventory all applications that link against libsoup and prioritize patching internet-facing or user-driven clients.

Patch Information

Distribution maintainers have released fixed libsoup packages. Red Hat addresses this issue in RHSA-2025:8292, and Debian LTS ships fixed packages through its security archive. The upstream patch adds a NULL check before the affected dereference inside soup_auth_digest_authenticate().

Workarounds

  • Avoid initiating HTTP requests to untrusted servers from libsoup-based applications until patches are applied.
  • Restrict outbound HTTP traffic from sensitive workloads to a vetted allowlist of destinations.
  • Disable or avoid HTTP Digest authentication in client configurations where the option exists, preferring stronger authentication schemes over TLS.
bash
# Configuration example: patch libsoup on supported distributions
# Red Hat Enterprise Linux
sudo dnf update libsoup libsoup3 --refresh

# Debian / Ubuntu
sudo apt-get update
sudo apt-get install --only-upgrade libsoup2.4-1 libsoup-3.0-0

# Verify installed version
rpm -q libsoup libsoup3        # RHEL family
dpkg -l | grep libsoup         # Debian family

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechLibsoup

  • SeverityMEDIUM

  • CVSS Score6.5

  • EPSS Probability0.46%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-476
  • Technical References
  • Red Hat Security Errata RHSA-2025:8292

  • Red Hat CVE-2025-32910 Details

  • Red Hat Bug Report #2359354

  • Debian LTS Security Announcement
  • Related CVEs
  • CVE-2025-32908: libsoup HTTP/2 DoS Vulnerability

  • CVE-2026-2436: libsoup SoupServer DoS Vulnerability

  • CVE-2025-4948: libsoup HTTP Library DoS Vulnerability

  • CVE-2025-32913: libsoup NULL Pointer DOS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English